Security
No rights on your cluster. Per-project permissions. Agents under control.
graal is designed for your CISO’s review: a privilege-free installation, federated identities, a record of every action, and no data sent outside.
Isolation
What graal asks of your cluster
An access review does not have to take our documentation on trust: the rendered chart can be reviewed, object by object.
No rights on the cluster
No custom resources, no cluster-wide role: graal works with only the rights your platform team grants it.
See the technical specificationRestricted pods, no exceptions
Every pod, including your workloads, runs under PSA restricted: non-privileged user, Linux capabilities dropped, default seccomp profile.
A closed network per workload
Each run gets its own network policy: it cannot reach another project or another organization, and its egress is limited to authorized destinations.
Images under control
Workloads only pull images from authorized registries, pinned by digest: no arbitrary image starts.
Identity
Who can do what, on what
Roles and their holders are visible in the console, and revoked in the same place.

The roles of an organization: what each one can do, and on what.
Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).
Your SSO, your directory
OIDC or SAML federation, LDAP or Active Directory, enforceable multi-factor authentication.
The project is the unit of permissions
Roles per resource, groups from your directory, assignments revoked in one click.
One organization, one directory
Each organization has its own authentication realm: isolation is an identity boundary, not a column in a table.
AI agents
Agents that act, under your rules
An AI agent holds permissions like anyone else: it authenticates, is scoped to one project, is traced, and can be revoked.


The Agents panel: connected agents, their permissions, and every tool call they make, live.
Real graal console interface, not retouched; fictional demonstration data (tenant energie-demo — people, projects and tokens are invented).
One service account per project
The agent acts under its own identity, never under that of the person who created it.
Human approval
Sensitive actions wait for approval from an authorized person other than the agent’s creator.
Per-agent policies
Allowed operations, projects, maximum cost and time windows, agent by agent.
No destructive tool enabled by default
An agent creates, runs and schedules; deleting remains an explicit choice on your side.
Visible and revocable
Every call shows up live in the console; removing a permission takes effect on the next request.
The model of your choice
Hosted on your premises or with the provider you select: an external model only receives what the tools return to it.
Secrets
Encrypted in the database, delivered in memory
A workload needs to reach a database; the password that allows it must neither be readable in clear text nor travel.
Encrypted in the database
Sealed with AES-256-GCM, with one key per organization derived from a root key by HKDF-SHA256. The secret’s name is used as authenticated data: moved elsewhere, it no longer decrypts.
Delivered in memory
A workload receives its secrets at startup, in memory: they appear neither in pod specs nor in logs.
Referenced, never copied
Connectors and pipelines reference a secret by name: exported code contains no password.
Audit
Every action leaves a record
The same trail for people and for agents, reviewable and exportable.
- Who did what, on which resource, with what result, person or agent
- The source address of every request
- Logins, access denials and revocations
- Approvals granted or refused to agents
- A trail you can export to your SIEM
- Costs and quotas, project by project
Nothing leaves
What graal does not send, and what it ships
The platform needs no outside service to work.
No telemetry
graal sends nothing to the vendor: no usage statistics, no error reports, no data from your projects.
No third-party service
No SaaS, no external fonts, no external captcha: the platform works on a closed network.
A verifiable supply chain
Signed images pinned by digest, and a software bill of materials (SBOM) shipped with every release.
Reporting
Report a vulnerability
Write to security@graal.systems. We acknowledge, fix, and keep you informed until publication.
Put graal in front of your security teams
Rendered chart, list of requested rights, permission model and answers to your questionnaires: on request.